Privacy First by Architecture

Privacy Policy

Learn how All In One Tools protects your privacy through 100% client-side local processing and zero server storage.

Last updated: September 2026

100% Client-Side Processing

All image conversions, hashing, formatting, regex tests, and encryption execute directly in your browser using WebAssembly and JavaScript. Your files and inputs never leave your device.

Zero Server Storage

We maintain no database of user inputs. There is no cloud storage for processed documents, generated passwords, or cryptographic keys. When you close the page, your data is gone.

Local Storage Retention

Tools that support saving items (like the 2FA Authenticator vault) store data strictly in your browser's localStorage. We have zero access to this stored data.

Cookieless Analytics

We use Umami Analytics to understand general website traffic. Umami does not use tracking cookies, does not collect personal identifiers, and is fully compliant with GDPR and CCPA.

1. Information We Do Not Collect

Our engineering philosophy is simple: we cannot lose, leak, or sell data that we never possess. Specifically:

  • Files & Documents: Images, text files, CSV tables, and archives you drop into any tool are processed solely in memory by your browser.
  • Passwords & Keys: Passwords generated or tested, hash strings, and two-factor authentication secret keys are never transmitted to our servers.
  • Personal Identifying Information: We do not require accounts, logins, phone numbers, or payment info to use our tools.

2. Browser Local Storage & Data Clearing

Certain utility features persist configuration settings or vaults directly on your device using HTML5 Web Storage API (localStorage):

  • 2FA Authenticator: Secret keys and labels are kept in your browser's private storage so you can access your OTP codes on future visits.
  • Theme & Language Preferences: Your selected interface language is saved locally.

You can completely erase all local data at any time by clearing your browser's cache/cookies or resetting site data in your browser settings.

3. Infrastructure & Edge Request Logging

Like virtually all web services, our hosting and CDN providers record basic network-edge metadata (IP address, timestamp, request path, user-agent) strictly for DDoS mitigation, rate limiting, and operational stability. It is never linked to tool inputs.

4. User-Initiated Issue Reporting

If you choose to use the Report Issue button, you explicitly decide whether to include a screenshot. You provide a description and an optional contact email. This information is submitted only upon your explicit confirmation.

5. Third-Party Services

To sustain free availability, production builds may display advertisements through Google AdSense. You can opt out of personalized advertising by visiting Google Ad Settings (adssettings.google.com).

6. Contact Us

If you have questions or feedback about this Privacy Policy or our security practices, feel free to submit feedback using the Report Issue button at the bottom of any page or visit ii2d.com.